Model Inversion
Model inversion се опитва да възстанови свойства или representative data за training subjects от model outputs/gradients .
Какво е
Model inversion се опитва да възстанови свойства или representative data за training subjects от model outputs/gradients.
Как работи
Особено при overfit models или rich confidence outputs, attacker използва optimization/inference, за да реконструира чувствителни features.
Как да се предотврати
Privacy-preserving training, differential privacy където е подходяща, reduce excessive confidence detail, regularization, access control и privacy testing.
Най-ефективни защити
Подредени по приоритет — P0 е мястото, от което се започва.